Control
`POST /v1/control/team/{id}/mfa-reset`: clears somebody's second factor.
The path back in for a person who has lost both their phone and their recovery codes. It is deliberately an admin action rather than a self-service one: a self-service reset is a way around the second factor.
Errors
Returns 401 without a session, 403 without TeamManage, 404 when the
reviewer is not in the caller’s tenant, and 503 when the enrolment or
session store cannot be written.
POST
`POST /v1/control/team/{id}/mfa-reset`: clears somebody's second factor.

